PT-2005-3367 · Kayako · Kayako Liveresponse
James Bercegay
·
Publicado
2005-12-31
·
Atualizado
2016-10-18
·
CVE-2005-2462
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kayako liveResponse versions 2.x
Description
The issue allows local users and possibly remote attackers to gain privileges by exploiting the fact that passwords are recorded in plaintext in the URL when a user logs in.
Recommendations
For Kayako liveResponse versions 2.x, consider disabling the login functionality until a fix is available to prevent passwords from being recorded in plaintext. Restrict access to the login module to minimize the risk of exploitation. Avoid using the password parameter in the affected login endpoint until the issue is resolved.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Kayako Liveresponse